## Recommended Service and Infrastructure Sizing

Here is a comprehensive list of Institutional Vault AWS-recommended services and infrastructure sizes:

| Service Name | Resource Type          | CPU Cores | Memory (GB) | AWS Specification |
| -------------| -----------------------| ----------| ------------ | ----------------- |
| Wallet service| microservice container | 1         | 1           | container         |
| Message Broker| microservice container | 0.5       | 0.5         | container         |
| MPA Policy-nodes (x3)| virtual machine instance | 4         | 16          | m5.xlarge        |
| Relational Database | database PaaS     | 2         | 4           | t4g.medium       |

## Deployed AWS Infrastructure Components

The CDK long-lived, wallet, and Policy Node stacks provision these AWS services and supporting infrastructure:

| Supporting service               | Technology           |
| ----------------------------------| --------------------|
| Infrastructure deployment          | CDK / CloudFormation |
| Certificate management             | ACM                  |
| Container orchestration           | ECS (Fargate)       |
| Policy Node compute               | EC2                  |
| Confidential computing             | Nitro Enclaves      |
| Secrets management                 | Secrets Manager     |
| Key management                     | KMS                  |
| Database management                | RDS (PostgreSQL)    |
| DNS management                     | Route 53, Cloud Map |
| Monitoring and logging             | CloudWatch          |
| Software distribution              | ECR                  |
| Network isolation and management   | VPC                  |
| Load balancing                     | Application Load Balancer (ALB) |
| Content delivery                   | CloudFront          |
| Object storage                     | S3                   |
| Shared file storage                | EFS                  |
| Log export                         | Lambda               |
| Web application firewall           | WAF (optional IP allowlist) |

Authentication uses your customer OpenID Connect identity provider (OAuth/OIDC). The wallet integrates with that IdP; Blockdaemon does not provision the IdP in your AWS account.

## Service Limits and Quotas

You don't need to request any limit increases for default Service Quotas when using the Automated AWS deployment tooling.

## Network and Firewall Ports

The table below summarizes the minimum network and firewall rules required for the Institutional Vault AWS ECS deployment. Wallet and message-broker workloads run on ECS (Fargate). Policy Nodes run on EC2 with Nitro Enclaves and initiate **outbound-only** connections to the message broker (no inbound broker connectivity from the internet).

| Source   | Destination                                       | Protocol / Port(s)                                | Purpose / Notes                                                           |
| -------- | -------------------------------------------------| ------------------------------------------------- | ------------------------------------------------------------------------- |
| External users / administrators (External Network) | CloudFront distribution / Application Load Balancer (ALB) | TCP 443 _(HTTP 80 opt.)_                 | Wallet UI / API, approval flows, and webhook endpoints. HTTP 80 is used only for HTTPS redirect. |
| Wallet ECS tasks, MPA Policy Node EC2 hosts        | Amazon RDS for PostgreSQL                          | TCP 5432                                     | Application database traffic from wallet services and MPA Policy Nodes to RDS. |
| Wallet ECS tasks, EVM tracker ECS tasks             | NATS ECS service / internal Network Load Balancer | TCP 4222, 8222, 8443                        | Internal message bus (NATS) used by wallet services for orchestration messaging. |
| MPA Policy Node EC2 hosts (Nitro)                   | NATS internal endpoint / NLB (`nats` Cloud Map or private hostname) | TCP 4222 (mTLS)                                 | Policy Node broker connectivity. Policy Nodes connect outbound only to the broker. |
| Wallet ECS tasks, MPA Policy Node EC2 hosts        | VPC DNS / Amazon Route 53 Resolver                 | UDP/TCP 53                                 | DNS resolution inside the VPC (including Cloud Map service discovery names). |
| Wallet ECS tasks, MPA Policy Node EC2 hosts        | AWS regional APIs (Secrets Manager, KMS, ECR, S3, CloudWatch, STS) | TCP 443                                     | Outbound HTTPS for secrets, key management, image pulls, config/objects, logging, and AWS control-plane APIs. Policy Nodes use this for OIDC key discovery and optionally Secrets Manager / KMS (including Nitro attestation-gated secret release). |
| Wallet ECS tasks, MPA Policy Node EC2 hosts        | Customer OIDC identity provider                      | TCP 443                                     | Outbound HTTPS for identity and OIDC discovery / JWKS. |
| Wallet ECS tasks                                | External / internal blockchain node RPC endpoints    | TCP 443, 8555–8556, 8546                        | Node RPC connectivity for on-chain operations over HTTPS and WebSocket. |
| Wallet ECS tasks                                | Blockdaemon API (`https://svc.blockdaemon.com`)     | TCP 443                                     | Blockchain data, staking, token, pricing, balance and transaction queries via Blockdaemon. |
| Wallet ECS tasks                                | WalletConnect relay (`wss://relay.walletconnect.com`) and Verify API (`https://verify.walletconnect.org`) | TCP 443                                     | WalletConnect v2 relay for dApp sessions and signing, plus domain verification / anti-phishing checks. |
| Wallet ECS tasks                                | ApproverApp Expo push service (`https://expo.host`)  | TCP 443                                     | Outbound push notifications to mobile devices via Expo push notification service. |
| Wallet ECS tasks                                | Customer SMTP relay (configured `host:port`) _(optional)_ | TCP 587, 465, or as configured                 | Email notifications to approvers when SMTP relay is enabled. Required only when email notifications are configured. |
| Wallet ECS tasks                                | Chainalysis KYT API (`https://api.chainalysis.com`) _(optional)_ | TCP 443                                     | KYT compliance screening for withdrawal and deposit transactions. Required only when Chainalysis integration is enabled. |
| Wallet ECS tasks                                | Canton validator, scan API and DA Utilities (`https://api.utilities.digitalasset.com`) _(optional)_ | TCP 443, gRPC 443                                | Canton ledger, validator and scan API access, plus Digital Asset utility services. Required only when Canton/Daml blockchain support is enabled. |

These ports should be reflected in any perimeter firewall, VPC security groups / network ACLs, and on-prem network controls used in the deployment.
